Apple released iOS and macOS updates to fix a flaw in font processing that could trigger a denial-of-service condition or memory corruption. Apple released iOS and macOS updates to address a medium-severity flaw, tracked as CVE-2025-43400, in font processing that could trigger a denial-of-service condition or memory corruption. The CVE-2025-43400 flaw is an out-of-bounds write […]
A vulnerability was found in MLEHMANN JSON::XS up to 4.03 on Perl. It has been classified as critical. Impacted is an unknown function. Performing manipulation results in heap-based buffer overflow.
This vulnerability is reported as CVE-2025-40928. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability has been found in VMware Tools on Windows and classified as critical. The impacted element is an unknown function. This manipulation causes incorrect authorization.
This vulnerability is registered as CVE-2025-41246. The attack requires access to the local network. No exploit is available.
The affected component should be upgraded.
A vulnerability was found in rhboot shim up to 15.7 on ARM and classified as critical. The impacted element is the function mirror_one_esl of the file mok.c of the component mok. Such manipulation leads to format string.
This vulnerability is referenced as CVE-2023-40546. The attack needs to be initiated within the local network. No exploit is available.
Applying a patch is advised to resolve this issue.
A vulnerability marked as critical has been reported in rhboot shim on 32-bit. Impacted is the function verify_sbat_section. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2023-40548. The attack can only be initiated within the local network. No exploit exists.
A vulnerability classified as critical has been found in Red Hat OpenShift AI. The impacted element is an unknown function of the component ClusterRole Handler. This manipulation causes permission issues.
This vulnerability is handled as CVE-2025-10725. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in shim 3.8.15/8. It has been declared as problematic. This affects an unknown part of the component MZ Binary Format Handler. The manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2023-40551. The attack requires a local approach. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in rhboot shim. The affected element is the function verify_buffer_authenticode of the file shim.c. The manipulation results in out-of-bounds read.
This vulnerability was named CVE-2023-40549. The attack needs to be approached within the local network. There is no available exploit.
A vulnerability classified as problematic has been found in rhboot shim. The impacted element is the function verify_buffer_sbat. This manipulation causes out-of-bounds read.
The identification of this vulnerability is CVE-2023-40550. The attack needs to be done within the local network. There is no exploit available.